Methods and systems for security software patch type detection
Abstract
Methods and systems are provided for security patch type detection of software patches. A software patch for a software product may be received. For example, the software patch may be received by a computing device. A pre-patch code property graph and a post-patch code property graph may be determined. For example, the pre-patch code property graph and the post-patch code property graph may be determined based on the software patch and/or the pre-patch source code and the post-patch source code respectively. A combined patch code property graph may be determined. For example, the combined patch code property graph may be determined based on the pre-patch code property graph and the post-patch code property graph. A patch type for the software patch may be determined. For example, the patch type may be determined based on the combined patch code property graph and/or a machine-learning prediction model.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
receiving, by a computing device, a software patch for a software product; determining, based on the software patch, a pre-patch code property graph and a post-patch code property graph; determining, based on the pre-patch code property graph and the post-patch code property graph, a combined patch code property graph; and determining, based on the combined patch code property graph, a patch type for the software patch.
2 . The method of claim 1 , further comprising:
receiving pre-patch source code for the software product associated with the software patch; and receiving post-patch source code for the software product, wherein the pre-patch code property graph is further determined based on the pre-patch source code and wherein the post-patch code property graph is further based on the post-patch source code.
3 . The method of claim 2 , further comprising:
determining a plurality of functions in the pre-patch source code; determining, based on the software patch, a portion of the plurality of functions associated with the software patch; and removing a second portion of the plurality of functions not associated with the software patch from the pre-patch source code.
4 . The method of claim 2 , further comprising:
determining a plurality of functions in the post-patch source code; determining, based on the software patch, a portion of the plurality of functions associated with the software patch; and removing a second portion of the plurality of functions not associated with the software patch from the post-patch source code.
5 . The method of claim 1 , wherein the combined patch code property graph comprises one or more of a deleted component, an added component, or a context component.
6 . The method of claim 1 , wherein the patch type for the software patch comprises one of a security patch or a non-security patch.
7 . The method of claim 1 , further comprising performing a backward slicing technique on at least a portion of the combined patch code property graph.
8 . The method of claim 1 , further comprising performing a forward slicing technique on at least a portion of the combined patch code property graph.
9 . The method of claim 1 , further comprising transforming the combined patch code property graph into a numeric format.
10 . The method of claim 1 , wherein determining the patch type for the software patch is further based on a machine-learning prediction model.
11 . An apparatus comprising:
one or more processors; and memory storing processor-executable instructions that, when executed by the one or more processors, cause the apparatus to:
receive a software patch for a software product;
determine, based on the software patch, a pre-patch code property graph and a post-patch code property graph;
determine, based on the pre-patch code property graph and the post-patch code property graph, a combined patch code property graph; and
determine, based on the combined patch code property graph, a patch type for the software patch.
12 . The apparatus of claim 11 , wherein the processor-executable instructions, when executed by the one or more processors, further cause the apparatus to:
receive pre-patch source code for the software product associated with the software patch; and receive post-patch source code for the software product, wherein the processor-executable instructions that, when executed by the one or more processors, cause the apparatus to determine the pre-patch code property graph, cause the apparatus to further determine the pre-patch code property graph based on the pre-patch source code and wherein the processor-executable instructions that, when executed by the one or more processors, cause the apparatus to determine the post-patch code property graph, cause the apparatus to further determine the post-patch code property graph based on the post-patch source code.
13 . The apparatus of claim 12 , wherein the processor-executable instructions, when executed by the one or more processors, further cause the apparatus to:
determine a plurality of functions in the post-patch source code; determine, based on the software patch, a portion of the plurality of functions associated with the software patch; and remove a second portion of the plurality of functions not associated with the software patch from the post-patch source code.
14 . The apparatus of claim 12 , wherein the processor-executable instructions, when executed by the one or more processors, further cause the apparatus to:
determine a plurality of functions in the post-patch source code; determine, based on the software patch, a portion of the plurality of functions associated with the software patch; and remove a second portion of the plurality of functions not associated with the software patch from the post-patch source code.
15 . The apparatus of claim 11 , wherein the patch type for the software patch comprises one of a security patch or a non-security patch.
16 . The apparatus of claim 11 , wherein the processor-executable instructions, when executed by the one or more processors, further cause the apparatus to perform one or more of a backward slicing technique or a forward slicing technique on at least a portion of the combined patch code property graph.
17 . The apparatus of claim 11 , wherein the processor-executable instructions that, when executed by the one or more processors, cause the apparatus to determine the patch type for the software patch, further cause the apparatus to determine the patch type based on a machine-learning prediction model.
18 . A system comprising:
a first computing device configured to send a software patch; and a second computing device configured to:
receive the software patch;
determine, based on the software patch, a pre-patch code property graph and a post-patch code property graph;
determine, based on the pre-patch code property graph and the post-patch code property graph, a combined patch code property graph; and
determine, based on the combined patch code property graph, a patch type for the software patch.
19 . The system of claim 18 , wherein the second computing device is further configured to determine the patch type based on a machine-learning prediction model.
20 . The system of claim 18 , wherein the patch type for the software patch comprises one of a security patch or a non-security patch.Join the waitlist — get patent alerts
Track US2024411886A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.